composer/composer · error · RuntimeException
Advisory for could not be loaded as a full advisory from
Error message
Advisory for ${name} could not be loaded as a full advisory from ${getRepoName()}
${var_export($data, true)} What it means
Thrown inside the advisory-creation closure during security advisory fetching when a remote advisory cannot be hydrated into a full SecurityAdvisory and partial advisories are not allowed. The data dump is included to aid diagnosis. This signals the upstream repository returned incomplete or malformed advisory data.
Solutions
- Inspect the var_export dump in the error to see which fields are missing.
- If you control the advisory feed, ensure it returns all fields required for a full SecurityAdvisory.
- If you cannot fix the feed, allow partial advisories via the appropriate audit option/config so the loader degrades gracefully.
- Verify you are running a Composer version compatible with the feed's advisory schema.
Defensive patterns
Strategy: try-catch
Try / catch
try {
$advisories = $repo->getSecurityAdvisories($packages, false);
} catch (\RuntimeException $e) {
if (str_contains($e->getMessage(), 'could not be loaded as a full advisory')) { /* retry with allowPartialAdvisories=true, or report upstream */ }
else { throw $e; }
} Prevention
- Ensure your advisory feed returns all fields required by SecurityAdvisory.
- Keep Composer updated to match the feed's schema version.
- Allow partial advisories if you can tolerate degraded output.
When it happens
Trigger: When $allowPartialAdvisories is false (the caller requires full advisories) and PartialSecurityAdvisory::create returns only a PartialSecurityAdvisory (missing required fields like patches, sources, or proper linking). The check at line 726 triggers.
Common situations: A custom/private packagist-like server returning advisory payloads missing required fields. Composer run with strict advisory settings against a repo whose advisory schema is incomplete. Version skew between Composer and the advisory feed.
Related errors
- Invalid filter summary received from
- A repository of type "package" contains an invalid package…
- Cannot use --before/--after with boolean repository values
- Composer rollback failed: an empty signature was downloaded…
- Composer rollback failed: could not download the signature…
AI-assisted analysis of composer/composer@c435d285c9 (2026-08-07).
Data as JSON: /api/errors/9134904a56288e18.
Report an issue: GitHub.
Appendix: source
Thrown at src/Composer/Repository/ComposerRepository.php:727
// respect available-package-patterns / available-packages directives from the repo
if ($this->hasAvailablePackageList) {
foreach ($packageConstraintMap as $name => $constraint) {
if (!$this->lazyProvidersRepoContains(strtolower($name))) {
unset($packageConstraintMap[$name]);
}
}
}
$parser = new VersionParser();
/**
* @param array<mixed> $data
* @param string $name
* @return ($allowPartialAdvisories is false ? SecurityAdvisory|null : PartialSecurityAdvisory|SecurityAdvisory|null)
*/
$create = function (array $data, string $name) use ($parser, $allowPartialAdvisories, &$packageConstraintMap): ?PartialSecurityAdvisory {
$advisory = PartialSecurityAdvisory::create($name, $data, $parser);
if (!$allowPartialAdvisories && !$advisory instanceof SecurityAdvisory) {
throw new \RuntimeException('Advisory for '.$name.' could not be loaded as a full advisory from '.$this->getRepoName() . PHP_EOL . var_export($data, true));
}
if (!$advisory->affectedVersions->matches($packageConstraintMap[$name])) {
return null;
}
return $advisory;
};
if ($this->securityAdvisoryConfig['metadata'] && ($allowPartialAdvisories || $apiUrl === null)) {
$promises = [];
foreach ($packageConstraintMap as $name => $constraint) {
$name = strtolower($name);
// skip platform packages, root package and composer-plugin-api
if (PlatformRepository::isPlatformPackage($name) || '__root__' === $name) {
continue;
}
View on GitHub (pinned to c435d285c9)